基于知识图谱和强化学习的攻击预测方法
首发时间:2024-07-18
摘要:针对当前攻击预测方法存在适用性差、知识利用率低、难以应对多样化的攻击威胁等问题,提出一种基于知识图谱和强化学习的攻击预测方法。首先构建网络安全知识图谱和攻击场景知识图谱,其次,融合知识表示学习和深度强化学习方法、提出攻击预测知识推理模型rlbtranse,针对攻击场景网络拓扑和攻击场景知识图谱,分别生成主机间攻击路径和单主机内攻击路径,最终实现完整攻击路径预测。在模拟实验场景数据集上的实验结果表明,rlbtranse相较于目前典型先进方法,平均倒数排名(mean reciprocal rank,mrr)和hits@1分别提高了10.1%和9.3%,与其他攻击预测方法的对比实验进一步验证了所提方法具有更好的适用性和可解释性。
关键词:
for information in english, please click here
attack prediction method based on knowledge graph and reinforcement learning
abstract:to address the problems of poor applicability, low knowledge utilization and difficulty in dealing with diverse attack threats for current attack prediction methods,, an attack prediction method based on knowledge graph and reinforcement learning was proposed. firstly, a cyber security knowledge graph and an attack scenario knowledge graph were constructed. secondly, the knowledge representation learning and deep reinforcement learning methods were integrated to propose an attack prediction knowledge reasoning model rlbtranse. based on the attack scenario network topology and attack scenario knowledge graph, inter-host attack paths and single-host attack paths were generated respectively, and finally the complete attack path prediction was realized. experimental results on the simulated experimental scenario data set show that, compared with current typical advanced methods, rlbtranse improves the mean reciprocal rank (mrr) and hits@1 by 10.1% and 9.3% respectively. comparative experiments with other attack prediction methods also verify the better pplicability and interpretability of this method.
keywords:
论文图表:
引用
导出参考文献
no.****
同行评议
勘误表
基于知识图谱和强化学习的攻击预测方法
评论
全部评论0/1000